+

Search Tips   |   Advanced Search

Configuring dynamic and nested group support for the SunONE or iPlanet Directory Server

Configure dynamic and nested groups to simplify WAS security management and increase its effectiveness and flexibility.

To use dynamic and nested groups with WAS security, we must be running WAS v6.1 or later. Refer to LDAP dynamic and nested groups for more information on this topic.

  1. In the console for WebSphere Application Server, click Security > Global security.

  2. Under User account repository, click the Available realm definitions drop-down list, select Standalone LDAP registry, and click Configure.

  3. Select SunONE for the type of LDAP server.

  4. Select the Ignore case for authorization option.

  5. Under Additional Properties, click Advanced LDAP user registry settings.

  6. Change the Group filter setting to &(cn=%v)(objectclass=ldapsubentry)).

  7. Change the Group member ID map setting to nsRole:nsRole.

  8. Click Apply or OK to validate the changes.


Related concepts


Standalone LDAP registries


Related tasks


Configure LDAP user registries
Locate user group memberships in a LDAP registry
Dynamic and Nested groups - IBM Security Directory Server
LDAP directory servers